Is this a complete step-up from unikernel-based OSs such as MirageOS or could it also use unikernels for improved security?
EDIT to Add: Just remembered that MILS separation kernel vendors (eg INTEGRITY-178B) have been doing this for over a decade with combinations such as sep kernel, Ada runtime for critical stuff, and user-mode VM's for legacy stuff. Long proven approach that mainstream is just catching up to.
But I haven't quite had time to figure it out myself yet; I've been interested in exploring Geode for a while.
So, it's a proven approach that could be implemented in GenodeOS and probably easier given others were bare-bones.